ietf-openpgp
[Top] [All Lists]

Re: [openpgp] Fingerprint, Base32 or Base32C?

2015-04-27 15:49:27
On Mon, Apr 27, 2015 at 4:40 PM, Christoph Anton Mitterer
<calestyo(_at_)scientia(_dot_)net> wrote:
On Mon, 2015-04-27 at 14:10 -0400, Phillip Hallam-Baker wrote:
I would like opinions on whether we should put a running checksum on
the fingerprint encoding or not.
I'm a bit unsure about the use of this,... can you elaborate on the
benefits you think are reached with that?!

Isn't the FP already checksum enough by itself?
Adding another checksum over the fingerprint shouldn't give more
security, or does it (since if it would be so simple to forge similarly
looking FPs that the user may type in by accident we'd have completely
different problems)?

I guess adding a checksum over the fingerprint will just tempt people to
only verify that checksum.

The idea is that when someone is typing in the fingerprint, the client
can perform a parity check to see if the fingerprint data is correct
as the user is typing rather than waiting to the end.

_______________________________________________
openpgp mailing list
openpgp(_at_)ietf(_dot_)org
https://www.ietf.org/mailman/listinfo/openpgp